HelloZeroNet / zeronet.io

ZeroNet - Decentralized websites using Bitcoin crypto and BitTorrent network
https://zeronet.io
GNU General Public License v2.0
49 stars 54 forks source link

HSTS rather than JavaScript Redirect #13

Closed jerry-wolf closed 7 years ago

jerry-wolf commented 7 years ago

Please support HSTS against protocol downgrade attacks. As far as I know, some internet service provider in China like hijacking HTTP connection for monitoring and inserting ADs. So they can modify the page to enforce HTTP connnection through reverse proxy.

If possible, please add zeronet.io to HSTS preload list: https://hstspreload.appspot.com/

HelloZeroNet commented 7 years ago

Thanks for suggestion, submitted:

Success

zeronet.io is now pending inclusion in the HSTS preload list!

Please make sure that zeronet.io continues to satisfy all preload requirement, or it will be removed. Please revisit this site over the next few weeks to check on the status of your domain.

Also consider scanning for TLS issues using SSL Labs.